QNAP kayıtları
qnap üreticisine ait 636 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 14 · %2,2
- Silahlaştırılmış
- 18 · %2,8
- Pre-auth RCE
- 66
- Düzeltme kaydı olan
- %0,3
- Yayından KEV’e ortanca
- 573 gün
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference83
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')74
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')58
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')57
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')46
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')45
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
636 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
96Hemen | CVE-2019-7195Silahlaştırılmış | This external control of file name or path vulnerability allows remote attackers to access or modify system files.qnap · photo station · CWE-22 | Kritik9,8 | KEV | %89,7 | 5 Ara 2019 |
95Hemen | CVE-2019-7192Silahlaştırılmış | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.qnap · photo station · CWE-863 | Kritik9,8 | KEV | %88,1 | 5 Ara 2019 |
94Hemen | CVE-2019-7194Silahlaştırılmış | This external control of file name or path vulnerability allows remote attackers to access or modify system files.qnap · photo station · CWE-22 | Kritik9,8 | KEV | %83,1 | 5 Ara 2019 |
92Hemen | CVE-2022-27593Silahlaştırılmış | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.qnap · photo station · CWE-610 | Kritik9,1 | KEV | %87,9 | 8 Eyl 2022 |
92Hemen | CVE-2021-28799Silahlaştırılmış | Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)qnap · hybrid backup sync · CWE-285 | Kritik9,8 | KEV | %78,3 | 12 May 2021 |
87Hemen | CVE-2023-47565Silahlaştırılmış | An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.qnap · qvr firmware · CWE-78 | Yüksek8,8 | KEV | %73,3 | 8 Ara 2023 |
79Bu hafta | CVE-2020-2509Silahlaştırılmış | Command Injection Vulnerability in QTS and QuTS heroqnap · qts · CWE-77 | Kritik9,8 | KEV | %34,0 | 17 Nis 2021 |
78Bu hafta | CVE-2018-19949Silahlaştırılmış | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.qnap · qts · CWE-20 | Kritik9,8 | KEV | %28,4 | 28 Eki 2020 |
73Bu hafta | CVE-2019-7193Silahlaştırılmış | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.qnap · qts · CWE-20 | Kritik9,8 | KEV | %14,4 | 5 Ara 2019 |
70Bu hafta | CVE-2020-2506Silahlaştırılmış | improper access control vulnerability in Helpdeskqnap · helpdesk · CWE-284 | Kritik9,8 | KEV | %2,0 | 3 Şub 2021 |
63Bu hafta | CVE-2018-19953Silahlaştırılmış | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.qnap · qts · CWE-79 | Orta6,1 | KEV | %28,8 | 28 Eki 2020 |
60Bu hafta | CVE-2023-47218Silahlaştırılmış | QTS, QuTS hero, QuTScloudqnap · qts · CWE-77 | Yüksek8,3 | — | %89,9 | 12 Şub 2024 |
59Planlayın | CVE-2017-6360Kavram kanıtı | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectqnap · qts · CWE-78 | Kritik9,8 | — | %66,1 | 23 Mar 2017 |
57Planlayın | CVE-2018-19943Silahlaştırılmış | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.qnap · qts · CWE-79 | Orta5,4 | KEV | %21,5 | 28 Eki 2020 |
56Planlayın | CVE-2017-6361Kavram kanıtı | QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.qnap · qts · CWE-78 | Kritik9,8 | — | %56,8 | 23 Mar 2017 |
49Planlayın | CVE-2018-0706Silahlaştırılmış | Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access seqnap · q\'center | Yüksek8,8 | — | %48,3 | 16 Tem 2018 |
47Planlayın | CVE-2017-6359Kavram kanıtı | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectorqnap · qts · CWE-78 | Kritik9,8 | — | %26,9 | 23 Mar 2017 |
46Planlayın | CVE-2018-0707Silahlaştırılmış | Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticatedqnap · q\'center · CWE-78 | Yüksek7,2 | — | %58,8 | 16 Tem 2018 |
46Planlayın | CVE-2024-27130Kavram kanıtı | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-120 | Yüksek8,8 | — | %37,5 | 21 May 2024 |
46Planlayın | CVE-2024-21899İstismar yok | QTS, QuTS hero, QuTScloudqnap · qts · CWE-287 | Kritik9,8 | — | %24,4 | 8 Mar 2024 |
45Planlayın | CVE-2023-23368İstismar yok | QTS, QuTS hero, QuTScloudqnap · qts · CWE-78 | Kritik9,8 | — | %18,8 | 3 Kas 2023 |
44Planlayın | CVE-2017-13067Silahlaştırılmış | QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 andqnap · qts | Kritik9,8 | — | %16,7 | 14 Eyl 2017 |
44Planlayın | CVE-2021-28809İstismar yok | Missing Authentication for Critical Function in RTRR Server in HBS3qnap · hybrid backup sync · CWE-284 | Kritik9,8 | — | %16,1 | 8 Tem 2021 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2019-719596Hemen
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90qnap · photo station5 Ara 2019
- CVE-2019-719295Hemen
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %88qnap · photo station5 Ara 2019
- CVE-2019-719494Hemen
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83qnap · photo station5 Ara 2019
- CVE-2022-2759392Hemen
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %88qnap · photo station8 Eyl 2022
- CVE-2021-2879992Hemen
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %78qnap · hybrid backup sync12 May 2021
- CVE-2023-4756587Hemen
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %73qnap · qvr firmware8 Ara 2023
- CVE-2020-250979Bu hafta
Command Injection Vulnerability in QTS and QuTS hero
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %34qnap · qts17 Nis 2021
- CVE-2018-1994978Bu hafta
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %28qnap · qts28 Eki 2020
- CVE-2019-719373Bu hafta
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %14qnap · qts5 Ara 2019
- CVE-2020-250670Bu hafta
improper access control vulnerability in Helpdesk
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %2qnap · helpdesk3 Şub 2021
- CVE-2018-1995363Bu hafta
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %29qnap · qts28 Eki 2020
- CVE-2023-4721860Bu hafta
QTS, QuTS hero, QuTScloud
YüksekCVSS 8,3SilahlaştırılmışEPSS %90qnap · qts12 Şub 2024
- CVE-2017-636059Planlayın
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vect
KritikCVSS 9,8Kavram kanıtıEPSS %66qnap · qts23 Mar 2017
- CVE-2018-1994357Planlayın
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %21qnap · qts28 Eki 2020
- CVE-2017-636156Planlayın
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
KritikCVSS 9,8Kavram kanıtıEPSS %57qnap · qts23 Mar 2017
- CVE-2018-070649Planlayın
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access se
YüksekCVSS 8,8SilahlaştırılmışEPSS %48qnap · q\'center16 Tem 2018
- CVE-2017-635947Planlayın
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vector
KritikCVSS 9,8Kavram kanıtıEPSS %27qnap · qts23 Mar 2017
- CVE-2018-070746Planlayın
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated
YüksekCVSS 7,2SilahlaştırılmışEPSS %59qnap · q\'center16 Tem 2018
- CVE-2024-2713046Planlayın
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions.
YüksekCVSS 8,8Kavram kanıtıEPSS %38qnap · qts21 May 2024
- CVE-2024-2189946Planlayın
QTS, QuTS hero, QuTScloud
KritikCVSS 9,8İstismar yokEPSS %24qnap · qts8 Mar 2024
- CVE-2023-2336845Planlayın
QTS, QuTS hero, QuTScloud
KritikCVSS 9,8İstismar yokEPSS %19qnap · qts3 Kas 2023
- CVE-2017-1306744Planlayın
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and
KritikCVSS 9,8SilahlaştırılmışEPSS %17qnap · qts14 Eyl 2017
- CVE-2021-2880944Planlayın
Missing Authentication for Critical Function in RTRR Server in HBS3
KritikCVSS 9,8İstismar yokEPSS %16qnap · hybrid backup sync8 Tem 2021